monitor-memory

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file contains 'Non-Negotiable' instructions for autonomous operation, explicitly commanding the agent to 'NEVER stop' and stating that waiting for human status checks is 'UNACCEPTABLE'. This attempts to override the agent's standard safety and operational protocols regarding human-in-the-loop control.
  • [REMOTE_CODE_EXECUTION]: Probes P08 and P09 in probes/tier4_projects.py read project paths from ~/.agent_skills_targets and execute code within those directories using python3 and shell scripts. This allows for arbitrary code execution if an attacker can modify the targets file.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the subprocess module across multiple files (e.g., probes/tier1_autofix.py, probes/tier2_persona.py, probes/tier3_smoke.py) to execute external binaries and other agent skills.
  • [COMMAND_EXECUTION]: The P04 probe in probes/tier1_data.py uses importlib to dynamically load and execute Python code from a computed filesystem path (.pi/skills/taxonomy/taxonomy.py).
  • [DATA_EXFILTRATION]: The P29 probe in probes/tier1_local_memory.py scans and reads sensitive local files from ~/.claude/projects/*/memory/*.md, which may contain private agent context or user data, and synchronizes them to an ArangoDB instance.
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface in probe P29 by ingesting untrusted markdown files from the local filesystem and upserting them as 'lessons' into the memory database without sanitization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — monitor-memory